pachca-bots
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill utilizes the official vendor CLI tool
@pachca/clifrom the NPM registry for all bot management and interaction tasks. This is a legitimate vendor resource.- [SAFE]: Documentation provides explicit instructions for secure webhook implementation, including HMAC-SHA256 signature verification and timestamp validation to prevent replay attacks.- [SAFE]: Credentials are handled through user-provided tokens passed via environment variables or command-line flags, which is standard practice for CLI-based integrations.- [SAFE]: The skill provides instructional guidance for various automation scenarios without including any hidden commands, obfuscated code, or unauthorized network operations.
Audit Metadata